Application properties
Property|Description|Default
Property|Description|Default
User management and access control based on user groups
You can set up WorkFusion User Management (Keycloak) to authenticate users based on identities from external providers.
User Federation
Install Java
Secrets Vault use cases
You can set the two-factor authentication flow right after installation or any time later. When you enable two-factor authentication after installation, make sure to set the flow before you configure user roles.
Instead of mapping attributes and roles to individual users, you can create groups of users sharing common attributes and role mappings.
To deactivate users means to disable them after a configured inactivity period. For the Workfusion realm, the period is set to 90 days by default, implying that all users inactive for more than 90 days are disabled automatically. For all other realms, the default value is zero days, meaning the User deactivation feature is off, and users won't be deactivated automatically.
To update the database connections for the CT vault, do as follows:
Sensitive customer information is protected by encryption at the Data Store level. However, the same data is used in Manual Tasks, namely, in Worker answers from WorkSpace, thus persisting in system tables without encryption.
Sensitive customer information is protected by encryption at the Data Store level. However, the same data is used in Manual Tasks, namely, in worker answers from WorkSpace, thus persisting in system tables without encryption.
WorkFusion User Management is based on the Keycloak Identity Provider integrated into the out-of-the-box WorkFusion package to implement Access Control List (ACL).
Superset is an open-source analytics tool that WorkFusion has integrated into its Product to monitor various process metrics. The tool is installed along with the Product, and the Superset-based dashboards become available from Control Tower immediately after installation. To start working with Superset-based dashboards, you only need to configure acess for users.
The role-based access mechanism (RBAC) limits access to data through Analytics dashboards based on the following filter categories:
Microsoft Windows uses a global certificate storage to keep certificates. The certificates must be imported to each workspace, to enable the browser to pass the certificate chain check successfully.
The document describes the integration of ADFS SSO with WorkFusion services.
Framework License
WorkFusion User Management features two levels of roles:
In Control Tower, the Role Management page lists all roles available for the application users and allows managing associated permissions.
Each realm comprises a set of clients and users with assigned roles. Realms are isolated from one another and let you manage and authenticate only the users that belong to them.
The data stored in Secrets Vault is not shown in recordings, logs, system files, or bot configs. It allows sharing scripts with other users without exposing confidential data.
To manage the secure properties, install the designated utility on the main installation server:
As soon as a user logs into a realm, WorkFusion User Management maintains their session while keeping track of their activities. Admins can view the data on all or particular user sessions and log out users of all or a particular session.
Each authenticated WorkFusion user can manage their account via the User Account Service:
Users always belong to and are created within a particular realm or imported to a realm from an external identity or storage provider.
To access any Workspace functionality, each user must have a role and permissions assigned to them.
The WorkFusion platform (previously IA Cloud Enterprise) v10.2 no longer supports qualifications. Instead, WorkSpace 2.0 employs a new approach to managing user permissions and restrictions, where:
The Work.AI platform uses internal Vault as KMS for MinIO encryption by default. The following guide describes how to switch KMS after the installation.
Starting from v10.2.1, a migration tool is available as part of the platform installer, enabling you to seamlessly migrate users, groups, qualifications, roles, and related mappings.
For working with REST API with an enabled Identity Provider (IDP), you cannot use your IDP ID or password. The recommended approach is to
s3
Secrets Vault API enables credentials management.
Secrets Vault plugins provide the functionality to manage Secrets Vault. Secrets Vault plugins work using the /secrets-vault WorkFusion Rest API. To learn more, refer to Secrets Vault API.
Property|Description|Required
By default, after Work.AI is installed, the Administrator Role has ultimate permissions regarding the User Management and Control Tower. It is very convenient to give all permissions to a person who sets up the environment to the organization's needs. However, after the initial environment setup, your organization may want to involve more people in administration while limiting their responsibilities and the platform capabilities with which they can interact.
To manage the access to Superset dashboards and related components, use standard Control Tower roles and permissions. To view or change the Superset-related permissions in Control Tower, navigate to System setting > Role management.
The WorkFusion User Management UI comprises the following clients that are available by default:
Transparent Data Encryption (TDE) is the MSSQL feature to encrypt database (DB) data and transaction log without changing an application. The DB engine encrypts or decrypts data during the query execution.
To validate the accessibility of an S3 object from a different host, follow the steps below:
The guide describes the procedure of updating TLS certificates (server.crt, server.key, and ca.crt) on the already installed WorkFusion platform environment.
This guide describes the update of passwords for the installed WorkFusion platform. The guide may be helpful in the following cases:
Create the following users on the corresponding servers before the installation.
The WorkFusion API lets you launch, post data to, and receive results from the WorkFusion platform automatically. Using it, you can manage simple tasks and more complex Business Processes (BPs) representing a workflow of various manual and automated tasks.